{"api_version":"1","generated_at":"2026-06-09T16:04:51+00:00","cve":"CVE-2019-13529","urls":{"html":"https://cve.report/CVE-2019-13529","api":"https://cve.report/api/cve/CVE-2019-13529.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-13529","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-13529"},"summary":{"title":"CVE-2019-13529","description":"An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2019-10-09 16:15:00","updated_at":"2019-10-15 16:54:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/154789/SMA-Solar-Technology-AG-Sunny-WebBox-1.6-Cross-Site-Request-Forgery.html","name":"http://packetstormsecurity.com/files/154789/SMA-Solar-Technology-AG-Sunny-WebBox-1.6-Cross-Site-Request-Forgery.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"SMA Solar Technology AG Sunny WebBox 1.6 Cross Site Request Forgery ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.us-cert.gov/ics/advisories/icsa-19-281-01","name":"https://www.us-cert.gov/ics/advisories/icsa-19-281-01","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"SMA Solar Technology AG Sunny WebBox | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-13529","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13529","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"13529","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sma","cpe5":"sunny_webbox","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13529","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sma","cpe5":"sunny_webbox","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13529","vulnerable":"1","versionEndIncluding":"1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sma","cpe5":"sunny_webbox_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-13529","ASSIGNER":"ics-cert@hq.dhs.gov","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"SMA Solar Technology AG","product":{"product_data":[{"product_name":"Sunny WebBox","version":{"version_data":[{"version_value":"Firmware Version 1.6 and prior"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CROSS-SITE REQUEST FORGERY (CSRF) CWE-352"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.us-cert.gov/ics/advisories/icsa-19-281-01","url":"https://www.us-cert.gov/ics/advisories/icsa-19-281-01"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/154789/SMA-Solar-Technology-AG-Sunny-WebBox-1.6-Cross-Site-Request-Forgery.html","url":"http://packetstormsecurity.com/files/154789/SMA-Solar-Technology-AG-Sunny-WebBox-1.6-Cross-Site-Request-Forgery.html"}]},"description":{"description_data":[{"lang":"eng","value":"An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation."}]}},"nvd":{"publishedDate":"2019-10-09 16:15:00","lastModifiedDate":"2019-10-15 16:54:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:sma:sunny_webbox_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.6","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:sma:sunny_webbox:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"13529","Ordinal":"151889","Title":"CVE-2019-13529","CVE":"CVE-2019-13529","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"13529","Ordinal":"1","NoteData":"An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"13529","Ordinal":"2","NoteData":"2019-10-09","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"13529","Ordinal":"3","NoteData":"2019-10-10","Type":"Other","Title":"Modified"}]}}}